Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Lador
Technical ID: osx.lador
APT GROUP
Malware family identifying osx.lador. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-17
View profile →
Kuiper
Technical ID: osx.kuiper
APT GROUP
Malware family identifying osx.kuiper. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-17
View profile →
Komplex
Technical ID: osx.komplex
APT28
APT GROUP
Malware family identifying osx.komplex. Origin and technical characteristics tracked via Malpedia.
Also known as: SedUploader • JHUHUGIT • JKEYSKW
Updated: 2017-02-15
View profile →
Kitmos
Technical ID: osx.kitmos
APT GROUP
Malware family identifying osx.kitmos. Origin and technical characteristics tracked via Malpedia.
Also known as: KitM
Updated: 2018-03-17
View profile →
KeySteal
Technical ID: osx.keysteal
APT GROUP
According to SentinelOne, KeySteal targets files with the .keychain and keychain-db file extensions in the following locations.
Updated: 2025-11-19
View profile →
Keydnap
Technical ID: osx.keydnap
APT GROUP
Malware family identifying osx.keydnap. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-09-01
View profile →
KeRanger
Technical ID: osx.keranger
APT GROUP
Malware family identifying osx.keranger. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
KANDYKORN
Technical ID: osx.kandykorn
Lazarus Group
APT GROUP
Malware family identifying osx.kandykorn. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-01-14
View profile →
JokerSpy
Technical ID: osx.jokerspy
APT GROUP
Malware family identifying osx.jokerspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-11
View profile →
Janicab
Technical ID: osx.janicab
Evilnum
APT GROUP
According to Patrick Wardle, this malware persists a python script as a cron job. Steps: 1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'. 2. Appends its new job to this file. 3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.
Updated: 2023-02-21
View profile →
Interception
Technical ID: osx.interception
Lazarus Group
APT GROUP
Malware family identifying osx.interception. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-14
View profile →
InsidiousGh0st
Technical ID: osx.insidiousgh0st
Unfading Sea Haze
APT GROUP
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports Quic. Variants in GO.
iMuler
Technical ID: osx.imuler
APT GROUPespionageadvanced
The threat was a multi-stage malware displaying a decoy that appeared to the victim as a Chinese language article on the long-running dispute over the Diaoyu Islands; an array of erotic pictures; or images of Tibetan organisations. It consisted of two stages: Revir was the dropper/downloader and Imuler was the backdoor capable of the following operations: - capture screenshots - exfiltrate files to a remote computer - send various information about the infected computer - extract ZIP archive - download files from a remote computer and/or the Internet - run executable files
Also known as: Revir
Updated: 2019-09-19
View profile →
HZ RAT
Technical ID: osx.hz_rat
APT GROUP
Malware family identifying osx.hz_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-13
View profile →
HLOADER
Technical ID: osx.hloader
Lazarus Group
APT GROUP
Malware family identifying osx.hloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-01-14
View profile →
HiddenLotus
Technical ID: osx.hiddenlotus
APT GROUP
According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising itself as a document - in this case, an Adobe Acrobat file.
Updated: 2023-05-21
View profile →
GolangGhost
Technical ID: osx.golangghost
WageMole
APT GROUP
Malware family identifying osx.golangghost. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-29
View profile →
Gmera
Technical ID: osx.gmera
APT GROUP
According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading app created for Mac users. Research shows that there are two variants of this malware, one detected as Trojan.MacOS.GMERA.A and the other as Trojan.MacOS.GMERA.B. Cyber criminals proliferate GMERA to steal various information and upload it to a website under their control. To avoid damage caused by this malware, remove GMERA immediately.
Also known as: StockSteal • Kassi
Updated: 2023-05-16
View profile →
GIMMICK
Technical ID: osx.gimmick
APT GROUP
This multi-platform malware is a ObjectiveC written macOS variant dubbed GIMMICK by Volexity. This malware is a file-based C2 implant used by Storm Cloud.
Updated: 2022-03-25
View profile →
FULLHOUSE
Technical ID: osx.fullhouse
APT GROUP
Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group. Fullhouse is written in C/C++ and includes the capabilities of a tunneler and backdoor commands support such as shell command execution, file transfer, file managment, and process injection. C2 communications occur via HTTP and require configuration through the command line or a configuration file.
Updated: 2023-07-25
View profile →
FruitFly
Technical ID: osx.fruitfly
APT GROUP
Malware family identifying osx.fruitfly. Origin and technical characteristics tracked via Malpedia.
Also known as: Quimitchin
Updated: 2020-05-02
View profile →
FrostyFerret
Technical ID: osx.frostyferret
WageMole
APT GROUP
Malware family identifying osx.frostyferret. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-27
View profile →
FrigidStealer
Technical ID: osx.frigid_stealer
APT GROUP
According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.
Updated: 2025-02-19
View profile →
FriendlyFerret
Technical ID: osx.friendlyferret
WageMole
APT GROUP
Malware family identifying osx.friendlyferret. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-04
View profile →
FlexibleFerret
Technical ID: osx.flexibleferret
WageMole
APT GROUP
Malware family identifying osx.flexibleferret. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-04
View profile →
FlashBack
Technical ID: osx.flashback
APT GROUP
Malware family identifying osx.flashback. Origin and technical characteristics tracked via Malpedia.
Also known as: FakeFlash
Updated: 2024-07-08
View profile →
FinFisher
Technical ID: osx.finfisher
APT GROUP
Malware family identifying osx.finfisher. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-08
View profile →
FailyTale
Technical ID: osx.failytale
APT GROUP
Malware family identifying osx.failytale. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-04-04
View profile →
EvilQuest
Technical ID: osx.evilquest
APT GROUPfinancialhigh
According to PcRisk, EvilQuest (also known as ThiefQuest) is like many other malicious programs of this type - it encrypts files and creates a ransom message. In most cases, this type of malware modifies the names of encrypted files by appending certain extensions, however, this ransomware leaves them unchanged. It drops the "READ_ME_NOW.txt" in each folder that contains encrypted data and displays another ransom message in a pop-up window. Additionally, this malware is capable of detecting if certain files are stored on the computer, operates as a keylogger, and receives commands from a Command & Control server.
Also known as: ThiefQuest
Updated: 2023-01-02
View profile →
EvilOSX
Technical ID: osx.evilosx
APT GROUP
Malware family identifying osx.evilosx. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-26
View profile →
ElectroRAT
Technical ID: osx.electro_rat
APT GROUP
According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows, MacOS, and Linux users. Cyber criminals behind ElectroRAT target mainly cryptocurrency users. This RAT is distributed via the trojanized Jamm, eTrader, and DaoPoker applications.
Updated: 2023-05-16
View profile →
Eleanor
Technical ID: osx.eleanor
APT GROUPespionageadvanced
Eleanor comes as a drag-and-drop file utility called EasyDoc Converter. This application bundle wraps a shell script that uses Dropbox name as a disguise and installs three components: a hidden Tor service, a Pastebin agent and a web service with a PHP-based graphical interface. The Tor service transforms the victim’s computer into a server that provides attackers with full anonymous access to the infected machine via Tor-generated address. The Pastebin agent uploads the address in encrypted form to the Pastebin website where the attackers can obtain it. The web service is the main malicious component that provides the attackers with the control over the infected machine. After successful authentication, the interface offers several control panels to the attackers, allowing them to do the following actions: - Managing files - Listing processes - Connecting to various database management systems such as MySQL or SQLite - Connecting via bind/reverse shell - Executing shell command - Capturing and browsing images and videos from the victim’s webcam - Sending emails with an attachment
Updated: 2019-09-10
View profile →
EggShell RAT
Technical ID: osx.eggshell_rat
APT GROUP
Malware family identifying osx.eggshell_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-19
View profile →
Dummy
Technical ID: osx.dummy
APT GROUP
Malware family identifying osx.dummy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-06
View profile →
Dockster
Technical ID: osx.dockster
APT GROUP
Malware family identifying osx.dockster. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
DazzleSpy
Technical ID: osx.dazzle_spy
APT GROUP
Malware family identifying osx.dazzle_spy. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-07
View profile →
DarthMiner
Technical ID: osx.darthminer
APT GROUP
Malware family identifying osx.darthminer. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-12-19
View profile →
Dacls
Technical ID: osx.dacls
Lazarus Group
APT GROUP
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control infected computers remotely. Research shows that this malware is tied to Lazarus Group (a group of cyber criminals) and targets Linux and the Windows Operating System. Typically, cyber criminals use RATs to steal sensitive, confidential information, infect systems with other malware, and so on. In any case, no RAT is harmless and should be uninstalled immediately.
Updated: 2023-05-15
View profile →
Cthulhu Stealer
Technical ID: osx.cthulhu_stealer
APT GROUP
Malware family identifying osx.cthulhu_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-15
View profile →
Crossrider
Technical ID: osx.crossrider
APT GROUP
Malware family identifying osx.crossrider. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-05-11
View profile →
← PreviousPage 194 / 269Next →